Seven critical CVEs. CVSS 9.8. No workarounds. And not a single one is being exploited yet.

Cisco's IOS XE Software Security Hardening Release, published August 5, 2026, covers CVE-2026-20267 through CVE-2026-20273 in IOS XE and Catalyst SD-WAN. Cisco found them internally. That is the entire reason you still have time.

WHAT ACTUALLY HAPPENED

Cisco ran its own offensive testing against IOS XE and came back with seven flaws rated Critical at 9.8.

CVE-2026-20272 is improper neutralisation of special elements — the class that ends in command and OS injection. CVE-2026-20273 is improper input validation, with path traversal in scope. CVE-2026-20271 is insufficient control-flow management: race conditions, uncontrolled recursion, infinite loops.

They were discovered during internal security testing. There is no evidence of exploitation in the wild.

Cisco is explicit that there are no workarounds. Upgrading is the only remediation available.

WHY THE QUIET ADVISORIES ARE THE ONES THAT MATTER

Patching in most organisations is driven by pressure, not by risk. A CVE lands in CISA's KEV catalog, a deadline appears, and the change window materialises overnight.

This advisory has none of that. No exploitation, no KEV entry, no journalist calling. So it gets scheduled for the next maintenance cycle, and the next one after that.

Meanwhile the technical detail is public. A 9.8 in the operating system running your campus core, your WAN edge and your SD-WAN fabric is a target with a published starting point — and the gap between advisory and working exploit is measured in weeks now, not quarters.

Every KEV-driven emergency you have ever run started life as an advisory exactly like this one, on a Wednesday, that nobody prioritised.

The advantage of a pre-exploitation patch is that you get to choose the maintenance window. Later, the attacker chooses it.

WHAT TO DO NOW

INVENTORY YOUR IOS XE AND SD-WAN VERSIONS — you cannot schedule what you have not counted, and most estates are wider than the CMDB says.

PLAN THE UPGRADE NOW — with no workarounds, the fixed release is the only control that exists, so this belongs in a scheduled window this quarter.

RESTRICT MANAGEMENT PLANE ACCESS — while you wait, cut who can reach the management interfaces to a hardened jump path only.

TREAT NON-EXPLOITED CRITICALS AS A CLASS — build a rule that 9.8 with no workaround gets a window regardless of KEV status.

Patching before exploitation is not caution. It is the only time you are ahead.

How long does a critical network OS advisory take to reach a change window in your organisation — honestly?
Turn the analysis into a plan

The gap between knowing the risk and closing it is a purchase order and a weekend.

We specify, source and deploy the equipment that closes it — firewalls, segmentation, secure remote access — and we support it afterwards.